
UW researchers figured out how to bypass anti-deepfake markers on AI images
Academia and industry have focused on watermarking as the best way to fight deepfakes and "basically abandoned all other approaches," said Andre Kassis, a PhD candidate in computer science who led the research.
At a White House event in 2023, the leading AI companies — including OpenAI, Meta, Google and Amazon — pledged to implement mechanisms such as watermarking to clearly identify AI-generated content.
AI companies' systems embed a watermark, which is a hidden signature or pattern that isn't visible to a person but can be identified by another system, Kassis explained.
He said the research shows the use of watermarks is most likely not a viable shield against the hazards posed by AI content.
"It tells us that the danger of deepfakes is something that we don't even have the tools to start tackling at this point," he said.
The tool developed at the University of Waterloo, called UnMarker, follows other academic research on removing watermarks. That includes work at the University of Maryland, a collaboration between researchers at the University of California and Carnegie Mellon, and work at ETH Zurich.
Kassis said his research goes further than earlier efforts and is the "first to expose a systemic vulnerability that undermines the very premise of watermarking as a defence against deepfakes."
In a follow-up email statement, he said that "what sets UnMarker apart is that it requires no knowledge of the watermarking algorithm, no access to internal parameters, and no interaction with the detector at all."
When tested, the tool worked more than 50 per cent of the time on different AI models, a university press release said.
AI systems can be misused to create deepfakes, spread misinformation and perpetrate scams — creating a need for a reliable way to identify content as AI-generated, Kassis said.
WATCH | How to spot a deepfake:
How to spot a deepfake
4 months ago
AI-generated videos have sprung up all over social media. Recently, a scam has been using deepfakes of CBC's David Cochrane and Prime Minister Justin Trudeau. A deepfake of U.S. President Donald Trump and Elon Musk made headlines last week that involved feet. Here are some ways to detect them.
After AI tools became too advanced for AI detectors to work well, attention turned to watermarking.
The idea is that if we cannot "post facto understand or detect what's real and what's not," it's possible to inject "some
kind of hidden signature or some kind of hidden pattern" earlier on, when the content is created, Kassis said.
The European Union's AI Act requires providers of systems that put out large quantities of synthetic content to implement techniques and methods to make AI-generated or manipulated content identifiable, such as watermarks.
In Canada, a voluntary code of conduct launched by the federal government in 2023 requires those behind AI systems to develop and implement "a reliable and freely available method to detect content generated by the system, with a near term focus on audio-visual content (e.g., watermarking)."
Watermark removed 'within 2 minutes max'
Kassis said UnMarker can remove watermarks without knowing anything about the system that generated it, or anything about the watermark itself.
"We can just apply this tool and within two minutes max, it will output an image that is visually identical to the watermark image" which can then be distributed, he said.
"It kind of is ironic that there's billions that are being poured into this technology and then, just with two buttons that you
press, you can just get an image that is watermark-free."
Kassis said that while the major AI players are racing to implement watermarking technology, more effort should be put into finding alternative solutions.
Watermarks have "been declared as the de facto standard for future defence against these systems," he said.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CBC
an hour ago
- CBC
Digging deeper: Saskatchewan producers look for greener way to mine lithium
Saskatchewan is home to large lithium deposits and a handful of the province's mining companies are betting on a green approach to take them global. Lithium is the main element in batteries, powering everything from smartphones to electric vehicles (EVs), which made up 17 per cent of all new cars sold in Canada in 2024. According to the United States Geological Survey, the global demand for lithium was up by nearly 18 per cent last year. "Demand is expected to continue to grow and that's coming mainly in the form of EVs," said Paul Schubach, chief operating officer for EMP Metals Corporation. He said there's a strong international interest in lithium, of which nearly 95 per cent of the metal comes from countries like Australia, Chile, China and Argentina. The majority of the mineral is then processed in China, which dominates the manufacturing of electric vehicle batteries. Schubach said Canada is far behind when it comes to producing lithium. " There's a lot of attention right now on North America and the EV boom that was expected to be there just hasn't quite taken off yet," he said. Environmental concerns around mining lithium There are many ways that lithium can be mined, but not all of them are environmentally safe. For instance, in South America, lithium is mined through expansive salt pools that hold salty water containing metals and minerals. In places like Chile, Bolivia and Argentina, the salty water is pumped to the surface, where it sits in massive pools to naturally evaporate, separating lithium from the other minerals. However, the extraction of brine has been found to reduce water levels in these areas, which can contaminate water sources with dangerous materials, becoming a danger to humans and animals who depend on it. The other common way of getting lithium is strip mining, or open pit mining, where lithium is removed by digging into hard rock below the ground. This can cause groundwater to dry up in nearby lakes, rivers and streams. There's also toxic chemicals used that can leak into water sources if not properly managed. With so many risks, some experts say that while extracting lithium is important, it shouldn't be thought of as a magic solution to climate change just because it powers the EV industry. What does that mean for Saskatchewan? It's no secret to Saskatchewan producers that lithium production can pose a harm to the environment. That's why a handful of companies in the province are looking to change that by pioneering a new way of getting the mineral out of the ground. Benjamin Sparrow, CEO of Saltworks Technologies, said instead of using traditional methods like hard rock mining or strip mining, more producers are now using direct lithium extraction (DLE), which takes it right out of the ground, separates out the lithium and recycles the groundwater. "It's underway and specifically underway in Canada," Sparrow said. He said DLE has the smallest environmental footprint and a "very small" land footprint for wells, electricity and water. Evaporation ponds are often not using a freshwater resource. Instead, Sparrow said they use a brine that is not intended for farming, drinking or other means because it's low-quality water. "The environmental footprint is largely associated with the ponds themselves, and as long as the ponds and the geotech is done right, there should not be any environmental concerns," he said. Teresa Kramarz, a mining expert at the University of Toronto, cautions this type of technology is still being tested and has yet to be tried on a large commercial scale in Saskatchewan. She said while in theory it uses less water and land, it needs to be studied further. There's not a lot of research to demonstrate whether direct extraction uses less water than the salt ponds in South America, Kramarz said. She said the potential for the technology is promising, but it remains to be seen if it will be cost effective and widely used. What's stopping Saskatchewan's lithium industry from starting commercial production? Sparrow said what stands out about Saskatchewan's resource is there's a high concentration of lithium and it's close to the surface, so it's very cost effective to extract. Areas like Kindersley and Estevan, both have large reserves of an underground brine, or water, that contains lithium. Additionally, Sparrow points to the province's infrastructure and labour available from the oil and gas industry, which isn't the case for other regions. At the same time, the current cost for lithium is $8,000 to $10,000 a ton. Sparrow said while the low cost makes DLE technology not the most economic, that hasn't put a damper on the Saskatchewan mining industry. "Innovation can change the cost equation," Sparrow said. "And that's exactly the work that's underway in Saskatchewan to drive the cost down below today's market price." Saskatchewan mining companies are betting the demand for lithium will quickly outpace supply. Schubach said he is confident that will happen.


Globe and Mail
4 hours ago
- Globe and Mail
Billionaires Are Buying a Popular AI Index Fund That Could Turn $500 Per Month Into $432,300
Key Points Three prominent billionaire money managers bought shares of the Invesco QQQ Trust in the first quarter. The Invesco QQQ Trust is heavily invested in technology stocks likely to benefit from artificial intelligence. The fund achieved a total return of 1,560% in the last two decades, compounding at 15% annually. 10 stocks we like better than Invesco QQQ Trust › The Invesco QQQ Trust (NASDAQ: QQQ) is the fifth-most popular exchange-traded fund (ETF) worldwide as measured by assets under management. Several prominent billionaires added to their positions in the first quarter, as detailed below: Ken Griffin of Citadel Advisors added 2.2 million shares. The Invesco QQQ Trust now ranks as the third-largest position in the hedge fund, excluding options. Israel Englander of Millennium Management added 474,300 shares. The ETF now ranks among the 25 largest positions in the hedge fund, excluding options. Steven Cohen of Point72 Asset Management added 7,950 shares. The ETF remains a relatively small position in the hedge fund. Citadel, Millennium, and Point72 are three of the most profitable hedge funds in history as measured by net gains. That makes all three money managers good sources of inspiration, and individual investors should consider following their lead with this ETF. The Invesco QQQ Trust could turn $500 per month into $432,300 in 20 years. The Invesco QQQ Trust is heavily invested in technology companies likely to benefit from artificial intelligence The Invesco QQQ Trust measures the performance of the Nasdaq-100, an index that tracks the 100 largest nonfinancial companies listed on the Nasdaq Stock Exchange. The ETF has more than 60% of its assets invested in technology stocks, many of which are likely to benefit as the artificial intelligence (AI) revolution continues to unfold. The 10 largest holdings in the Invesco QQQ Trust are listed by weight below: Nvidia: 9.8% Microsoft: 8.7% Apple: 7.2% Amazon: 5.6% Broadcom: 5.3% Alphabet: 5% Meta Platforms: 3.5% Netflix: 2.8% Tesla 2.6% Costco Wholesale: 2.3% AI spending across hardware, software, and services is forecast to grow at 35.9% annually through 2030, according to Grand View Research. Several companies listed above should benefit. Amazon, Microsoft, and Alphabet are the three largest public cloud providers, meaning demand for AI infrastructure should be a tailwind. And Nvidia is the undisputed leader in data center GPUs, the most popular type of AI accelerator. Apple has introduced generative AI capabilities for iPhones. Meta Platforms is leaning on AI to increase user engagement across its social media platforms and improve outcomes for advertisers. Netflix recently started using generative AI to create content for movies and shows. Broadcom is the market leader in AI networking chips and custom AI accelerators, and Tesla recently launched an autonomous ride-hailing service. History says the Invesco QQQ Trust can turn $500 invested monthly into $432,300 in 20 years Excluding dividends, the Invesco QQQ Trust advanced 1,340% during the last two decades, which is equivalent to 14% annually. Including dividends, the index fund achieved a total return of 1,560%, compounding at 15% annually. I will assume a more modest return of 12% annually to introduce a margin of safety. At that pace, $500 invested monthly in the fund would be worth $105,200 in one decade and $432,300 in two decades. Some investors may prefer to save more or less each month, so the chart below shows how different contribution amounts would grow over time, assuming annual returns of 12%. Holding Period $200 Per Month $400 Per Month $600 Per Month 10 Years $42,100 $84,200 $126,300 20 Years $172,900 $345,800 $518,700 Returns were determined using the compound interest calculator. Investors need two more pieces of information. First, the Invesco QQQ Trust has been very volatile in the past due to its heavy exposure to technology stocks. The index fund fell more than 12% from its record high seven times in the last decade. Similar volatility is likely in the future. Second, the ETF has an expense ratio of 0.2%, meaning shareholders will pay $20 per year on every $10,000 invested. Comparatively, the average expense ratio on U.S. index funds and mutual funds was 0.34% in 2024. Should you invest $1,000 in Invesco QQQ Trust right now? Before you buy stock in Invesco QQQ Trust, consider this: The Motley Fool Stock Advisor analyst team just identified what they believe are the 10 best stocks for investors to buy now… and Invesco QQQ Trust wasn't one of them. The 10 stocks that made the cut could produce monster returns in the coming years. Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you'd have $625,254!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you'd have $1,090,257!* Now, it's worth noting Stock Advisor's total average return is 1,036% — a market-crushing outperformance compared to 181% for the S&P 500. Don't miss out on the latest top 10 list, available when you join Stock Advisor. See the 10 stocks » *Stock Advisor returns as of July 29, 2025 Trevor Jennewine has positions in Amazon, Nvidia, and Tesla. The Motley Fool has positions in and recommends Alphabet, Amazon, Apple, Costco Wholesale, Meta Platforms, Microsoft, Netflix, Nvidia, and Tesla. The Motley Fool recommends Broadcom and recommends the following options: long January 2026 $395 calls on Microsoft and short January 2026 $405 calls on Microsoft. The Motley Fool has a disclosure policy.


Globe and Mail
8 hours ago
- Globe and Mail
Tyler Technologies Reports Strong Q2 2025 Earnings
Tyler Technologies ( (TYL)) has released its Q2 earnings. Here is a breakdown of the information Tyler Technologies presented to its investors. Elevate Your Investing Strategy: Take advantage of TipRanks Premium at 50% off! Unlock powerful investing tools, advanced data, and expert analyst insights to help you invest with confidence. Tyler Technologies, Inc. is a leading provider of software solutions and services for the public sector, offering innovative technology to enhance the efficiency and effectiveness of government operations. The company operates primarily in the enterprise software and platform technologies sectors, providing a range of solutions including public administration, courts and public safety, education, and property management. In its latest earnings report for the quarter ending June 30, 2025, Tyler Technologies reported a significant increase in total revenues, reaching $596.1 million, up from $541.0 million in the same period last year. The company's net income also saw a notable rise, reaching $84.6 million compared to $67.7 million in the previous year, indicating strong financial performance and growth. Key highlights from the report include a substantial increase in subscription revenues, which rose to $405.1 million from $333.7 million year-over-year, driven by strong demand for SaaS and transaction-based services. The company's operating income also improved, reaching $95.6 million, reflecting effective cost management and operational efficiency. Additionally, Tyler Technologies continued to invest in research and development, with expenses rising to $50.8 million, underscoring its commitment to innovation and product development. Despite challenges in professional services and maintenance revenues, Tyler Technologies has demonstrated resilience and adaptability in its business model, maintaining a robust financial position with total assets of $5.43 billion. The company's strategic focus on recurring revenue streams and technological advancements positions it well for sustained growth in the public sector market. Looking ahead, Tyler Technologies remains optimistic about its growth prospects, with management emphasizing continued investment in technology and expansion of its product offerings to meet the evolving needs of public sector clients. The company's strong financial performance and strategic initiatives are expected to drive further success in the coming quarters.